GPU VulnDB

Database/Control plane, storage & DevOps

rclone (rc API, operations/fsinfo): operations/fsinfo is reachable without authentication and accepts an

CVE-2026-41179Control plane, storage & DevOpscurated

Impact

operations/fsinfo is reachable without authentication and accepts an attacker-defined backend, so a caller can point it at a WebDAV remote whose bearer_token_command runs a shell command. Same practical outcome as the rcd RCE: code execution on the data-mover host and access to every credential in its config.

Who can reach it

Any host that can reach the rclone rc HTTP endpoint.

What to do

Upgrade rclone and restart all rc/serve instances. Rotate the credentials in the rclone config for anything the host could reach. Enforce authentication on the rc endpoint and keep it off shared networks.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.